EDBT 2026 Demo / reviewers in the wild / expert
Chenxiong Qian
dblp:147/2276
· DBLP profile ↗
30ranked-venue papers
3as first author
16since 2021 · last 2026
0000-0002-6201-6011ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 3 first-author · 11 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Computer networks · 2Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel Isolation
Yingjie Cao, Xiaogang Zhu 0001, Dean Sullivan, Lei Xue 0001, Chenxiong Qian, Minrui Yan, Xiapu Luo |
NDSS | 7 |
| 2026 | Specializing Language Models for Textual Fuzzing via Reinforcement Learning
Jiayi Lin 0007, Liangcai Su, Chenxiong Qian |
SP | 4 |
| 2026 | Bones of Contention: Exploring Query-Efficient Attacks Against Skeleton Recognition SystemsabstractSkeleton action recognition models have secured more attention than video-based ones in various applications due to privacy preservation and lower storage requirements. Skeleton data are typically transmitted to cloud servers for action recognition, with results returned to clients via Apps/APIs. However, the vulnerability of skeletal models against adversarial perturbations gradually reveals the unreliability of these systems. Existing black-box attacks all operate in a decision-based manner, resulting in numerous queries that hinder efficiency and feasibility in real-world applications. Moreover, all attacks off the shelf focus on only restricted perturbations, while ignoring model weaknesses when encountered with non-semantic perturbations. In this paper, we propose two query-effIcient Skeletal Adversarial AttaCks, ISAAC-K and ISAAC-N. As a black-box attack, ISAAC-K utilizes Grad-CAM in a surrogate model to extract key joints where minor sparse perturbations are then added to fool the classifier. To guarantee natural adversarial motions, we introduce constraints of both bone length and temporal consistency. ISAAC-K finds stronger adversarial examples on ℓ∞norm, which can encompass those on other norms. Exhaustive experiments substantiate that ISAAC-K can uplift the attack efficiency of the perturbations under 10 skeletal models. Additionally, as a byproduct, ISAAC-N fools the classifier by replacing skeletons unrelated to the action. We surprisingly find that skeletal models are vulnerable to large perturbations where the part-wise non-semantic joints are just replaced, leading to a query-free no-box attack without any prior knowledge. Based on that, four adaptive defenses are eventually proposed to improve the robustness of skeleton recognition models. Derui Wang, Minhui Xue 0001, Chenxiong Qian, Jin Song Dong 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | Identify as a Human Does: A Pathfinder of Next-Generation Anti-Cheat Framework for First-Person Shooter GamesabstractThe gaming industry has experienced substantial growth, but cheating in online games poses a significant threat to the integrity of the gaming experience. Cheating, particularly in first-person shooter (FPS) games, can lead to substantial losses for the game industry. Existing anti-cheat solutions have limitations, such as client-side hardware constraints, security risks, server-side unreliable methods, and both-sides suffer from a lack of comprehensive real-world datasets. To address these limitations, the paper proposes HAWK, a server-side FPS anti-cheat framework for the popular game CS:GO. HAWK utilizes machine learning techniques to mimic human experts’ identification process, leverages novel multi-view features, and is equipped with a well-defined workflow. HAWK is evaluated with the first large and real-world datasets containing multiple cheat types and cheating sophistication, and it exhibits promising efficiency and acceptable overheads, shorter ban times, higher recall and similar false positive rate compared to the in-use anti-cheat, and the ability to capture cheaters who evaded official inspections. Chenxin Sun, Qingyu Zhang 0005, Jiayi Lin 0007, Xiaojiang Du, Chenxiong Qian |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2026 | WizardMerge - Save Us from Merging without Any CluesabstractModern software development necessitates efficient version-oriented collaboration among developers. While Git is the most popular version control system, it generates unsatisfactory version merging results due to textual-based workflow, leading to potentially unexpected results in the merged version of the project. Although numerous merging tools have been proposed for improving merge results, developers remain struggling to resolve the conflicts and fix incorrectly modified code without clues. We present WizardMerge , an auxiliary tool that leverages merging results from Git to retrieve code block dependency on text and LLVM Intermediate Representation level and provide suggestions for developers to resolve errors introduced by textual merging. Rather than directly resolving these errors, the suggestions provide pigeonholed code blocks with their relevance and prioritized order within each category. To this end, developers can address the specific locations of these issues without manually analyzing their dependencies, thereby reducing the time and effort spent on conflict resolution tasks. Through the evaluation, we subjected WizardMerge to testing on 227 conflicts within five large-scale projects. The outcomes demonstrate that WizardMerge diminishes conflict merging time costs, achieving a 23.85% reduction. Beyond addressing conflicts, WizardMerge provides useful code block classifications and resolving orders for over 70% of the code blocks potentially affected by the conflicts. Notably, WizardMerge exhibits the capability to identify conflict-unrelated code blocks that require manual intervention yet are harmfully applied by Git during the merging. Qingyu Zhang 0005, Jiayi Lin 0007, Lanteng Lin, Chenxiong Qian |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2025 | ImportSnare: Directed 'Code Manual' Hijacking in Retrieval-Augmented Code Generation
Liangcai Su, Chenxiong Qian |
CCS | 3 |
| 2025 | Daredevil: Rescue Your Flash Storage from Inflexible Kernel Storage StackabstractExisting kernel storage stacks for NVMe SSDs struggle to address performance interference between I/O requests from tenants with different SLAs, leading to the multi-tenancy issue. Addressing this requires separating their I/O requests within the NVMe I/O queues (NQs). However, our analysis reveals that the static CPU core-NQ bindings of current storage stacks restrict their flexibility to achieve this goal. Ran Shu 0001, Jiayi Lin 0007, Qingyu Zhang 0005, Ziyue Yang 0002, Jie Zhang 0048, Yongqiang Xiong, Chenxiong Qian |
EuroSys | 8 |
| 2025 | How Far Are We from True Unlearnability?abstractHigh-quality data plays an indispensable role in the era of large models, but the use of unauthorized data for model training greatly damages the interests of data owners. To overcome this threat, several unlearnable methods have been proposed, which generate unlearnable examples (UEs) by compromising the training availability of data. Clearly, due to unknown training purposes and the powerful representation learning capabilities of existing models, these data are expected to be unlearnable for models across multiple tasks, i.e., they will not help improve the model's performance. However, unexpectedly, we find that on the multi-task dataset Taskonomy, UEs still perform well in tasks such as semantic segmentation, failing to exhibit $\textit{cross-task unlearnability}$. This phenomenon leads us to question: $\textit{How far are we from attaining truly unlearnable examples?}$ We attempt to answer this question from the perspective of model optimization. To this end, we observe the difference in the convergence process between clean and poisoned models using a simple model architecture. Subsequently, from the loss landscape we find that only a part of the critical parameter optimization paths show significant differences, implying a close relationship between the loss landscape and unlearnability. Consequently, we employ the loss landscape to explain the underlying reasons for UEs and propose Sharpness-Aware Learnability (SAL) to quantify the unlearnability of parameters based on this explanation. Furthermore, we propose an Unlearnable Distance (UD) to measure the unlearnability of data based on the SAL distribution of parameters in clean and poisoned models. Finally, we conduct benchmark tests on mainstream unlearnable methods using the proposed UD, aiming to promote community awareness of the capability boundaries of existing unlearnable methods. Liangcai Su, Chenxiong Qian |
ICLR | 3 |
| 2025 | Automatic Library Fuzzing through API Relation Evolvement
Jiayi Lin 0007, Qingyu Zhang 0005, Chenxin Sun, Hao Zhou 0043, Changhua Luo, Chenxiong Qian |
NDSS | 7 |
| 2025 | CherryPicker: A Parallel Solving and State Sharing Hybrid Fuzzing SystemabstractHybrid testing, combining fuzz testing and concolic execution, has emerged as an effective technique for bug discovery. However, concolic execution becomes the performance bottleneck when applied to real-world software. Despite numerous approaches to optimize seed scheduling, symbolic simulation, and constraint solving, concolic execution remains inefficient and ineffective due to two limitations. First, the concolic executor and fuzzer do not synchronize the testing state in real time, leading to the generation of numerous duplicate inputs in both concolic execution and the fuzzer. Second, the concolic executor overlooks the independence of constraint solving and solves constraints sequentially, which introduces significant slowdown. In this paper, we first conduct a study to identify these limitations in existing hybrid testing systems. We then propose a novel design for hybrid fuzzing,CherryPicker, where the fuzzer and concolic executor share testing states, and concolic execution runs in parallel mode. Finally, we evaluate our system using the LAVA-M benchmark and real-world software and compare it to state-of-the-art systems. The results demonstrate thatCherryPickeroutperforms current systems in terms of efficiency and effectiveness, delivering improved runtime performance, generating more intriguing inputs, and activating more code. Notably,CherryPickerexclusively uncovers six previously unknown bugs during the evaluation, which have been reported to developers, all of which have been confirmed with three CVEs assigned. Qingyu Zhang 0005, Jiayi Lin 0007, Chenxin Sun, Chenxiong Qian, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Unearthing Gas-Wasting Code Smells in Smart Contracts With Large Language ModelsabstractSmart contracts are automated programs stored on a blockchain, featuring unique attributes such as permissionlessness, trustlessness, immutability, and transparency. These properties underpin an array of unprecedented decentralized services. Compiled into bytecodes, Ethereum smart contracts are executed within the Ethereum Virtual Machine (EVM). Ethereum's distinct gas mechanism assigns a price to each bytecode execution, incentivizing resource-efficient computing. However, a disconnect exists between conventional coding practices and the less intuitive gas consumption computation mechanism, resulting in inadvertent gas wastage. Gas-wasting code smells at the source code level have been studied in various related works; however, the task of manually identifying such code smells by reading through codes and reasoning about them is both time-consuming and economically inefficient. In this work, we propose to leverage Large Language Models (LLMs), which have seen a surge in popularity recently, to facilitate undertaking the labor-intensive part of the code-smell-finding pipeline. In particular, we focus on Solidity, the predominant programming language for Ethereum smart contracts. Overall, we identified 26 gas-wasting code smells, out of which 13 were not presented in previous papers. On average, applying these code smells led to a reduction of approximately 10.534% in deployment costs and 21.528% in message call costs across our test codes. We further make a report on each of the identified code smells with associated example contracts sourced from either previous literature or recently deployed contracts. Jinan Jiang, Zihao Li 0001, Haoran Qin, Muhui Jiang, Xiapu Luo, Xiao-Ming Wu 0003, Haoyu Wang 0001, Yutian Tang, Chenxiong Qian, Ting Chen 0002 |
IEEE Trans. Software Eng. | 9 |
| 2024 | Beyond the Surface: Uncovering the Unprotected Components of Android Against Overlay Attack
Hao Zhou 0043, Shuohan Wu, Chenxiong Qian, Xiapu Luo, Haipeng Cai, Chao Zhang 0008 |
NDSS | 3 |
| 2024 | Revisiting Automotive Attack Surfaces: a Practitioners' PerspectiveabstractAs modern vehicles become increasingly complex in terms of both external attack surfaces and internal in-vehicle network (IVN) topology, ensuring their cybersecurity remains a challenge. Existing standards and regulations, such as WP29 R155e and ISO 21434, attempt to establish a baseline for automotive cybersecurity, but their sufficiency in addressing the evolving threats is unclear. To fill in this gap, we first carried out an in-depth interview study with 15 experts in automotive cybersecurity, uncovering the particular challenges encountered during security activities and the limitations of current regulations. We identified 20 key insights from the interview data, ranging from the challenges and gaps in the existing automotive security industry to the limitations and recommendations for current regulations. Notably, we discovered that the quality of threat cases provided by existing regulations is unsatisfactory, and the Threat Analysis and Risk Assessment (TARA) process is often highly inefficient due to the lack of automatic tools. In response to the above limitations, we first built an improved threat database for automotive systems using the collected interview data, which enhanced the existing database both quantitatively and qualitatively. Additionally, we present CarVal, a datalog-based approach designed to infer multi-stage attack paths in IVNs and calculate risk values, thereby making TARA more efficient for automotive systems. By applying CarVal to five real vehicles, we performed extensive security analysis based on the generated attack paths and successfully exploited the corresponding attack chains in the newly gateway-segmented IVN, uncovering new automotive attack surfaces that previous research failed to cover, including the in-vehicle browser, official mobile app, backend server, and in-vehicle malware. Pengfei Jing, Yingjie Cao, Le Yu 0002, Yuefeng Du 0006, Chenxiong Qian, Xiapu Luo, Sen Nie, Shi Wu |
SP | 7 |
| 2024 | Invisibility Cloak: Proactive Defense Against Visual Game Cheating
Chenxin Sun, Liangcai Su, Chenxiong Qian |
USENIX Security Symposium | 5 |
| 2023 | CydiOS: A Model-Based Testing Framework for iOS AppsabstractTo make an app stand out in an increasingly competitive market, developers must ensure its quality to deliver a better user experience. UI testing is a popular technique for quality assurance, which can thoroughly test the app from the users’ perspective. However, while considerable research has already studied UI testing on the Android platform, there is no research on iOS. This paper introduces CydiOS, a novel approach to performing model-based testing for iOS apps. CydiOS enhances the existing static analysis to build a more complete static model for the app under test. We propose an approach to retrieve runtime information to obtain real-time app context that can be mapped in the model. To improve the effectiveness of UI testing, we also introduce a potential-aware search algorithm to guide testing execution. We compare CydiOS with four representative algorithms(i.e., random, depth-first, stoat, and ape). We have evaluated CydiOS on 50 popular apps from App Store, and the results show that CydiOS outperforms other tools, achieving both higher code coverage and screen coverage. We open source CydiOS at https://github.com/SoftWare2022Testing/CydiOS, and a demo video can be found there. Shuohan Wu, Jianfeng Li 0006, Hao Zhou 0043, Yongsheng Fang, Kaifa Zhao, Haoyu Wang 0001, Chenxiong Qian, Xiapu Luo |
ISSTA | 7 |
| 2022 | DeView: Confining Progressive Web Applications by Debloating Web APIsabstractA progressive web application (PWA) becomes an attractive option for building universal applications based on feature-rich web Application Programming Interfaces (APIs). While flexible, such vast APIs inevitably bring a significant increase in an API attack surface, which commonly corresponds to a functionality that is neither needed nor wanted by the application. A promising approach to reduce the API attack surface is software debloating, a technique wherein an unused functionality is programmatically removed from an application. Unfortunately, debloating PWAs is challenging, given the monolithic design and non-deterministic execution of a modern web browser. In this paper, we present DeView, a practical approach that reduces the attack surface of a PWA by blocking unnecessary but accessible web APIs. DeView tackles the challenges of PWA debloating by i) record-and-replay web API profiling that identifies needed web APIs on an app-by-app basis by replaying (recorded) browser interactions and ii) compiler-assisted browser debloating that eliminates the entry functions of corresponding web APIs from the mapping between web API and its entry point in a binary. Our evaluation shows the effectiveness and practicality of DeView. DeView successfully eliminates 91.8% of accessible web APIs while i) maintaining original functionalities and ii) preventing 76.3% of known exploits on average. ChangSeok Oh, Sangho Lee 0001, Chenxiong Qian, Hyungjoon Koo, Wenke Lee |
ACSAC | 3 |
| 2020 | Slimium: Debloating the Chromium Browser with Feature SubsettingabstractToday, a web browser plays a crucial role in offering a broad spectrum of web experiences. The most popular browser, Chromium, has become an extremely complex application to meet ever-increasing user demands, exposing unavoidably large attack vectors due to its large code base. Code debloating attracts attention as a means of reducing such a potential attack surface by eliminating unused code. However, it is very challenging to perform sophisticated code removal without breaking needed functionalities because Chromium operates on a large number of closely connected and complex components, such as a renderer and JavaScript engine. In this paper, we present Slimium, a debloating framework for a browser (i.e., Chromium) that harnesses a hybrid approach for a fast and reliable binary instrumentation. The main idea behind Slimium is to determine a set of features as a debloating unit on top of a hybrid (i.e., static, dynamic, heuristic) analysis, and then leverage feature subsetting to code debloating. It aids in i) focusing on security-oriented features, ii) discarding unneeded code simply without complications, and iii)~reasonably addressing a non-deterministic path problem raised from code complexity. To this end, we generate a feature-code map with a relation vector technique and prompt webpage profiling results. Our experimental results demonstrate the practicality and feasibility of Slimium for 40 popular websites, as on average it removes 94 CVEs (61.4%) by cutting down 23.85 MB code (53.1%) from defined features (21.7% of the whole) in Chromium. Chenxiong Qian, Hyungjoon Koo, ChangSeok Oh, Taesoo Kim, Wenke Lee |
CCS | 1 |
| 2019 | RAZOR: A Framework for Post-deployment Software Debloating
Chenxiong Qian, Hong Hu 0004, Mansour Alharthi, Simon P. Chung, Taesoo Kim, Wenke Lee |
USENIX Security Symposium | 1 |
| 2019 | NDroid: Toward Tracking Information Flows Across Multiple Android ContextsabstractFor performance and compatibility reasons, developers tend to use native code in their applications (or simply apps). This makes a bidirectional data flow through multiple contexts, i.e., the Java context and the native context, in Android apps. Unfortunately, this interaction brings serious challenges to existing dynamic analysis systems, which fail to capture the data flow across different contexts. In this paper, we first performed a large-scale study on apps using native code and reported some observations. Then, we identified several scenarios where data flow cannot be tracked by existing systems, leading to uncaught information leakage. Based on these insights, we designed and implemented NDroid, an efficient dynamic taint analysis system that could track the data flow between both Java context and native context. The evaluation of real apps demonstrated the effectiveness of NDroid in identifying information leakage with reasonable performance overhead. Lei Xue 0001, Chenxiong Qian, Hao Zhou 0043, Xiapu Luo, Yajin Zhou, Yuru Shao, Alvin Chan Toong Shoon |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Enforcing Unique Code Target Property for Control-Flow IntegrityabstractThe goal of control-flow integrity (CFI) is to stop control-hijacking attacks by ensuring that each indirect control-flow transfer (ICT) jumps to its legitimate target. However, existing implementations of CFI have fallen short of this goal because their approaches are inaccurate and as a result, the set of allowable targets for an ICT instruction is too large, making illegal jumps possible. In this paper, we propose the Unique Code Target (UCT) property for CFI. Namely, for each invocation of an ICT instruction, there should be one and only one valid target. We develop a prototype called uCFI to enforce this new property. During compilation, uCFI identifies the sensitive instructions that influence ICT and instruments the program to record necessary execution context. At runtime, uCFI monitors the program execution in a different process, and performs points-to analysis by interpreting sensitive instructions using the recorded execution context in a memory safe manner. It checks runtime ICT targets against the analysis results to detect CFI violations. We apply uCFI to SPEC benchmarks and 2 servers (nginx and vsftpd) to evaluate its efficacy of enforcing UCT and its overhead. We also test uCFI against control-hijacking attacks, including 5 real-world exploits, 1 proof of concept COOP attack, and 2 synthesized attacks that bypass existing defenses. The results show that uCFI strictly enforces the UCT property for protected programs, successfully detects all attacks, and introduces less than 10% performance overhead. Hong Hu 0004, Chenxiong Qian, Carter Yagemann, Simon P. Chung, William R. Harris, Taesoo Kim, Wenke Lee |
CCS | 2 |
| 2018 | Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsabstractDuring system call execution, it is common for operating system kernels to read userspace memory multiple times (multi-reads). A critical bug may exist if the fetched userspace memory is subject to change across these reads, i.e., a race condition, which is known as a double-fetch bug. Prior works have attempted to detect these bugs both statically and dynamically. However, due to their improper assumptions and imprecise definitions regarding double-fetch bugs, their multi-read detection is inherently limited and suffers from significant false positives and false negatives. For example, their approach is unable to support device emulation, inter-procedural analysis, loop handling, etc. More importantly, they completely leave the task of finding real double-fetch bugs from the haystack of multi-reads to manual verification, which is expensive if possible at all. In this paper, we first present a formal and precise definition of double-fetch bugs and then implement a static analysis system - Deadline - to automatically detect double-fetch bugs in OS kernels. Deadline uses static program analysis techniques to systematically find multi-reads throughout the kernel and employs specialized symbolic checking to vet each multi-read for double-fetch bugs. We apply Deadline to Linux and FreeBSD kernels and find 23 new bugs in Linux and one new bug in FreeBSD. We further propose four generic strategies to patch and prevent double-fetch bugs based on our study and the discussion with kernel maintainers. Meng Xu 0001, Chenxiong Qian, Kangjie Lu, Michael Backes 0001, Taesoo Kim |
IEEE Symposium on Security and Privacy | 2 |
| 2018 | Rampart: Protecting Web Applications from CPU-Exhaustion Denial-of-Service Attacks
Wei Meng 0001, Chenxiong Qian, Shuang Hao 0001, Kevin Borgolte, Giovanni Vigna, Christopher Krügel, Wenke Lee |
USENIX Security Symposium | 2 |
| 2018 | Enhancing the Description-to-Behavior Fidelity in Android Apps with Privacy PolicyabstractSince more than 96 percent of mobile malware targets the Android platform, various techniques based on static code analysis or dynamic behavior analysis have been proposed to detect malicious apps. As malware is becoming more complicated and stealthy, recent research proposed a promising detection approach that looks for the inconsistency between an app's permissions and its description. In this paper, we first revisit this approach and reveal that using description and permission will lead to many false positives because descriptions often fail to declare all sensitive operations. Then, we propose exploiting an app's privacy policy and its bytecode to enhance the malware detection based on description and permissions. It is non-trivial to automatically analyze privacy policy and perform the cross-verification among these four kinds of software artifacts including, privacy policy, bytecode, description, and permissions. To address these challenging issues, we first propose a novel data flow model for analyzing privacy policy, and then develop a new system, named TAPVerifier, for carrying out investigation of individual software artifacts and conducting the cross-verification. The experimental results show that TAPVerifier can analyze privacy policy with a high accuracy and recall rate. More importantly, integrating privacy policy and bytecode level information can remove up to 59.4 percent false alerts of the state-of-the-art systems, such as AutoCog, CHABADA, etc. Le Yu 0002, Xiapu Luo, Chenxiong Qian, Shuai Wang 0012, Hareton K. N. Leung |
IEEE Trans. Software Eng. | 3 |
| 2017 | Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopabstractThe effectiveness of the Android permission system fundamentally hinges on the user's correct understanding of the capabilities of the permissions being granted. In this paper, we show that both the end-users and the security community have significantly underestimated the dangerous capabilities granted by the SYSTEM_ALERT_WINDOW and the BIND_ACCESSIBILITY_SERVICE permissions: while it is known that these are security-sensitive permissions and they have been abused individually (e.g., in UI redressing attacks, accessibility attacks), previous attacks based on these permissions rely on vanishing side-channels to time the appearance of overlay UI, cannot respond properly to user input, or make the attacks literally visible. This work, instead, uncovers several design shortcomings of the Android platform and shows how an app with these two permissions can completely control the UI feedback loop and create devastating attacks. In particular, we demonstrate how such an app can launch a variety of stealthy, powerful attacks, ranging from stealing user's login credentials and security PIN, to the silent installation of a God-mode app with all permissions enabled, leaving the victim completely unsuspecting. To make things even worse, we note that when installing an app targeting a recent Android SDK, the list of its required permissions is not shown to the user and that these attacks can be carried out without needing to lure the user to knowingly enable any permission. In fact, the SYSTEM_ALERT_WINDOW permission is automatically granted for apps installed from the Play Store and our experiment shows that it is practical to lure users to unknowingly grant the BIND_ACCESSIBILITY_SERVICE permission by abusing capabilities from the SYSTEM_ALERT_WINDOW permission. We evaluated the practicality of these attacks by performing a user study: none of the 20 human subjects that took part of the experiment even suspected they had been attacked. We also found that it is straightforward to get a proof-of-concept app requiring both permissions accepted on the official store. We responsibly disclosed our findings to Google. Unfortunately, since these problems are related to design issues, these vulnerabilities are still unaddressed. We conclude the paper by proposing a novel defense mechanism, implemented as an extension to the current Android API, which would protect Android users and developers from the threats we uncovered. Yanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke Lee |
IEEE Symposium on Security and Privacy | 2 |
| 2017 | Efficient Protection of Path-Sensitive Control Security
Ren Ding 0001, Chenxiong Qian, Chengyu Song, William Harris, Taesoo Kim, Wenke Lee |
USENIX Security Symposium | 2 |
| 2016 | Revisiting the Description-to-Behavior Fidelity in Android ApplicationsabstractSince more than 96% of mobile malware targets on Android platform, various techniques based on static code analysis or dynamic behavior analysis have been proposed to detect malicious applications. As malware is becoming more complicated and stealthy, recent research proposed a promising detection approach that looks for the inconsistency between an application's permissions and its description. In this paper, we revisit this approach and find that using description and permission will lead to many false positives. Therefore, we propose employing app's privacy policy and its bytecode to enhance description and permission for malware detection. It is non-trivial to automatically analyze privacy policy and perform the cross-verification among these four kinds of software artifacts including, privacy policy, bytecode, description, and permissions. We propose a novel data flow model for analyzing privacy policy, and develop a novel system, named TAPVerifier, for carrying out investigation of individual software artifacts and conducting the cross-verification. The experimental results show that TAPVerifier can analyze privacy policy with a high accuracy and recall rate. More importantly, integrating privacy policy and code level information removes 8.1%-65.5% false positives of existing systems based on description and permission. Le Yu 0002, Xiapu Luo, Chenxiong Qian, Shuai Wang 0012 |
SANER | 3 |
| 2015 | AndroidPerf: A cross-layer profiling system for Android applicationsabstractProfiling Android applications (or simply apps) is an important way to discover and locate various problems in apps, such as performance bottleneck, security loopholes, etc. Although many dynamic profiling systems for apps have been proposed, they are limited in dealing with the multiple-layer nature of Android and thus cannot reveal issues due to the underlying platform or poor interactions between different layers. Note that since apps usually run in Dalvik virtual machine (DVM) and each DVM is a process in Android's customized Linux kernel, a simple operation in DVM will lead to many function calls in different layers. In this paper, we propose AndroidPerf, a cross-layer profiling system, including the DVM layer, the system layer, and the kernel layer, for Android apps. It consists of one sub-system that performs cross-layer dynamic taint analysis to collect control flow and data flow information, and another subsystem that conducts instrumentation on all layers for collecting performance information. We have implemented AndroidPerf in 9,125 lines of C/C++ and 1,016 lines of Python scripts along with some modifications to Android's framework. Besides evaluating its functionality and overhead, we have applied AndroidPerf to reveal real performance issues through case studies. Lei Xue 0001, Chenxiong Qian, Xiapu Luo |
IWQoS | 2 |
| 2014 | Towards a scalable resource-driven approach for detecting repackaged Android applicationsabstractRepackaged Android applications (or simply apps) are one of the major sources of mobile malware and also an important cause of severe revenue loss to app developers. Although a number of solutions have been proposed to detect repackaged apps, the majority of them heavily rely on code analysis, thus suffering from two limitations: (1) poor scalability due to the billion opcode problem; (2) unreliability to code obfuscation/app hardening techniques. In this paper, we explore an alternative approach that exploits core resources, which have close relationships with codes, to detect repackaged apps. More precisely, we define new features for characterizing apps, investigate two kinds of algorithms for searching similar apps, and propose a two-stage methodology to speed up the detection. We realize our approach in a system named ResDroid and conduct large scale evaluation on it. The results show that ResDroid can identify repackaged apps efficiently and effectively even if they are protected by obfuscation or hardening systems. Yuru Shao, Xiapu Luo, Chenxiong Qian, Pengfei Zhu 0001, Lei Zhang 0006 |
ACSAC | 3 |
| 2014 | On Tracking Information Flows through JNI in Android ApplicationsabstractAndroid provides native development kit through JNI for developing high-performance applications (or simply apps). Although recent years have witnessed a considerable increase in the number of apps employing native libraries, only a few systems can examine them. However, none of them scrutinizes the interactions through JNI in them. In this paper, we conduct a systematic study on tracking information flows through JNI in apps. More precisely, we first perform a large-scale examination on apps using JNI and report interesting observations. Then, we identify scenarios where information flows uncaught by existing systems can result in information leakage. Based on these insights, we propose and implement NDroid, an efficient dynamic taint analysis system for checking information flows through JNI. The evaluation through real apps shows NDroid can effectively identify information leaks through JNI with low performance overheads. Chenxiong Qian, Xiapu Luo, Yuru Shao, Alvin Chan Toong Shoon |
DSN | 1 |
| 2014 | On Measuring One-Way Path Metrics from a Web ServerabstractMeasuring one-way path metrics can facilitate adaptive online services (e.g., Video streaming and CDN) tuning to improve quality of experience (QoE) of their clients. However, existing server-side measurement systems suffer from (i) measuring only few one-way path metrics, (ii) limited client-side support, and (iii) heavy overheads. In this paper, we propose and implement OWPScope, a novel system that can be deployed to any web server to measure four important one-way path metrics-packet loss, packet reordering, jitter, and capacity-without requiring software or plug in installation at their web clients. Moreover, OWPScope performs representative measurement by correlating only information gleaned from standard features in HTML5 (e.g., Navigation timing, resource timing), HTTP, and TCP. Our extensive evaluations in both a test bed and the Internet show that OWPScope can effectively measure one-way path metrics with low overhead. Xiapu Luo, Lei Xue 0001, Yuru Shao, Chenxiong Qian, Edmond W. W. Chan |
ICNP | 5 |